Again sent earlier. Thanks for the intervening comments about
vulnerabiliteis and versions.
A lot of issues and suggestions have been made and raised. My brief
response is that yes, according to nmap and my intention I had port 23,
for ssh (I moved it) and port 5900 open and the rpc port, I think. I'm
going by memory.
Theoretically the only pinhole in the ISP router firewall was port 23.
To use port 5900, you had to use an ssh tunnel.
My web server is on another machine. Since I only use it for
development, I don't leave it up.
My actual web pages are hosted externally on a vendor's box.
My experience with the upgrade treadmill is that it is a waste of time.
By its own admission (if a concept can have that) the new versions will
have issues and you need to upgrade. If the issues with an older
version don't affect you, then it is perfectly fine to use it. Why
upgrade and risk the fact that the new issues will affect your use case.
The developers for Fedora 13 were no smarter or dumber than the
developers who are writing Fedora 36. Or pick your distro of choice.
The issue with an older release is that nifty new things come out and
you can't really use them. But, if you run a VM with a recent version
of the distro, you can use them just fine.
The other issues is that if you are getting vendor support, they can
only reasonably commit to supporting a limited number of versions.
This is AMD hardware from '06.
-Gary
On Fri, Aug 05, 2022 at 06:19:54PM -0700, Rick Moen wrote:
> Quoting Brian E. Lavender (brian(a)brie.com):
>
> > Gary,
> >
> > You were running Fedora 13?
>
> If so, _that_ is likely a big problem. Fedora 13's initial release was
> May 25, 2010, and it was EOLed on June 24, 2011.
>
> Because Fedora. If you don't want to keep moving to newer versions,
> it's about the worst possible distro. (But it's possible Gary meant
> that he did _original_ installation 15 years ago, but has been following
> the recommended upgrade treadmill^W path.
>
> Linus Sphinx wrote:
>
> > https://www.bleepingcomputer.com/news/security/new-linux-malware-brute-forc…
>
> You know, I have a _lot_ of things to be grateful for, and somewhere on
> the list is the glad tidings that I don't need to rely on
> Bleepingcomputer.com for IT information.
>
> Over the past 1.5 months since its discovery, the new botnet used
> over 3,500 unique IPs worldwide to scan and attempt brute-forcing Linux
> SSH servers.
> [...]
> The SSH brute-forcing relies on a list of credentials downloaded from
> the [command and control server]. [...]
>
> *snore*
>
> So, doorknob-twisting for "joe accounts", like user=service
> password=manager and like that.
>
> Guestimate the math, and measure the lengthly setup and teardown times
> for remote connections to an sshd, and you'll find that
> dictionary-attacking an sshd with any reasonable rules set about
> password quality and length is going to take an appreciable fraction of
> the time to the heat death of the universe, to succeed.
>
> I mentioned upthread that a lot of IT device comes from gadget freaks.
> The _other_ common problem is that most security _articles_ are
> copied-pasted press releases from security/antimalware firms.
> So, they're big on shockhorror, and small on conveying understanding.
>
> I've only quick-glanced at this article about enforcing password policy
> via PAM, so won't swear to it being a good one:
> https://www.techrepublic.com/article/controlling-passwords-with-pam/
> Of course, if you're the -only- user, you ought to stick to decent
> passwords without PAM forcing you to. (Also, a user who can su to
> root has the power to overrule PAM. But if you do that, you have only
> yourself to blame for consequences.)
>
> _______________________________________________
> Lug-nuts mailing list -- lug-nuts(a)bigbrie.com
> To unsubscribe send an email to lug-nuts-leave(a)bigbrie.com
----- End forwarded message -----
Any thoughts on the Pale Moon web browser?
I was looking around on Honda's web site and they complained about my web browser being out of date. On that VM, its Firefox 84. I clicked on "learn more" hoping that Honda would tell me exactly why they wanted me to upgrade. It's not a bank, after all, and they offered me browser options.
Admittedly, I live under a rock. But, I had never heard of Pale Moon. I went to their home page and am going to give it a try.
I resist browser upgardes because they often change the layout, for no apparent reason. And, the new "features" are often things I don't like. Such as storing a bunch on info on my browser so they don't have to (which I suspect may be Honda's motive). So, if I was going to have to deal with I new layout anyhow, I decided to go for broke and try something actually new.
Security? Its a Honda site. Unless they want me to protect against malware from them, I don't get it.
-Gary
Well, I never heard of it and I don't care for Chromium. Are you using it? I forwarded my reply to the list because I thought it was your intention to reply there.
-Gary
On Mon, Oct 31, 2022 at 06:52:25AM -0700, bob r wrote:
> Gary,
> Is there any reason why you have not tried the Brave browser yet?
> Bob
>
> On Sun, Oct 30, 2022 at 6:38 PM Gary <saclug(a)garymcglinn.com> wrote:
>
> > I went to the Volkswagen site and my Firefox 84 had some problems. So, I
> > installed Firefox 106. The widgets/trim are ugly, but it didn't have any
> > issues on the Volkswagen site. Interestingly to me, the page layout was
> > completely different. Not sure what has come online recently as far as
> > what browsers have to support, but there is definitely something
> > substantial that is new.
> >
> > -Gary
> >
> > On Sat, Oct 29, 2022 at 06:36:07AM -0700, Gary wrote:
> > > OK, I've seen enough. In palemoon the "learn more" button on
> > Wolkswagens web site doesn't work. It doesn't seem to be recognized.
> > Works fine in old Firefox.
> > >
> > > -Gary
> > >
> > > On Sat, Oct 29, 2022 at 05:47:55AM -0700, Gary wrote:
> > > > Any thoughts on the Pale Moon web browser?
> > > >
> > > > I was looking around on Honda's web site and they complained about my
> > web browser being out of date. On that VM, its Firefox 84. I clicked on
> > "learn more" hoping that Honda would tell me exactly why they wanted me to
> > upgrade. It's not a bank, after all, and they offered me browser options.
> > > >
> > > > Admittedly, I live under a rock. But, I had never heard of Pale
> > Moon. I went to their home page and am going to give it a try.
> > > >
> > > > I resist browser upgardes because they often change the layout, for no
> > apparent reason. And, the new "features" are often things I don't like.
> > Such as storing a bunch on info on my browser so they don't have to (which
> > I suspect may be Honda's motive). So, if I was going to have to deal with
> > I new layout anyhow, I decided to go for broke and try something actually
> > new.
> > > >
> > > > Security? Its a Honda site. Unless they want me to protect against
> > malware from them, I don't get it.
> > > >
> > > > -Gary
> > > > _______________________________________________
> > > > Lug-nuts mailing list -- lug-nuts(a)bigbrie.com
> > > > To unsubscribe send an email to lug-nuts-leave(a)bigbrie.com
> > > _______________________________________________
> > > Lug-nuts mailing list -- lug-nuts(a)bigbrie.com
> > > To unsubscribe send an email to lug-nuts-leave(a)bigbrie.com
> > _______________________________________________
> > Lug-nuts mailing list -- lug-nuts(a)bigbrie.com
> > To unsubscribe send an email to lug-nuts-leave(a)bigbrie.com
> >
Hello list,
Finally have working firewall rules analysis code up
& running. This turns out to be a hard problem!
A lot of people have worked out the math, but there
are a ton of picky obstacles to applying them to real
sets of iptables rules. I hope to flesh out the code
over the next few months and am hoping for a release
(public open source) soon.
--
Charles Polisher
Hey Everyone,
I passed my check ride this last Friday for private pilot! woo hoo. This
has been what I call "Curiosity killed the cat adventure.", in the
figurative sense of course. ;-)
It was all partly inspired by work with Spark/Ada while I was at Sac State
and few guest lectures I gave to the CSC 201 class at Sac State on
Spark/Ada revolving around the implementation of Spark/Ada in the C130J
upgrades. While I found the use of Spark/Ada interesting in the C130J, I
couldn't help wondering what more is involved with the aircraft. So, I
took pilot training lessons! Well, it has been a lot of work. I can fly
a Cessna 172 now! It's not quite a C130J, but it sure gives that hands
on feel!
Here is an interesting paper!
https://www.sigada.org/ada_letters/dec2000/chapman-paper.pdf
Brian
--
Brian Lavender
http://www.brie.com/brian/
"There are two ways of constructing a software design. One way is to
make it so simple that there are obviously no deficiencies. And the other
way is to make it so complicated that there are no obvious deficiencies."
Professor C. A. R. Hoare
The 1980 Turing award lecture
I applied security updates to the server and I just want to make sure it
still works.
--
Brian Lavender
http://www.brie.com/brian/
"There are two ways of constructing a software design. One way is to
make it so simple that there are obviously no deficiencies. And the other
way is to make it so complicated that there are no obvious deficiencies."
Professor C. A. R. Hoare
The 1980 Turing award lecture